Bad Rabbit (S0606)
Initial Access
• Bad Rabbit spreads through drive-by
downloads on compromised websites,
masquerading as an Adobe Flash installer.
Execution
• Uses a fake Flash update to execute malicious
scripts, employing various Windows API calls
for actions.
Persistence
• Achieves persistence by modifying system
boot settings to load ransomware before the
OS.
Privilege Escalation
• Attempts to gain elevated privileges via UAC
bypass techniques.
Defense Evasion
• Uses legitimate names and locations to
masquerade its activities, encrypts files to
avoid detection.
Credential Access
• Employs Mimikatz to harvest credentials from
the victim's machine.
Discovery
• Enumerates network shares and machines for
further propagation.
Lateral Movement
• Utilizes EternalRomance exploit for SMB to
move laterally across networks.
Command and Control
• Communicates with C2 servers to receive
commands and exfiltrate data.
Exfiltration
• Exfiltrates collected data to attacker-controlled
servers.
Impact
• Encrypts user files and system disks,
demanding ransom for decryption keys.